How to implement VRF

How to implement VRF

By default ISP routers use one global routing table to forward traffic from different customers. This can lead to some issues like address overlapping, giant routing tables, etc.

To address these needs ISP can use VRF – Virtual Routing Forwarding or VPN Routing Forwarding. Customer interfaces are associated to a specific VPN routing table (secure). One thing to note is that this feature is commonly used with MPLS, when it’s not used with it it’s just called VRF Lite.

VRF Lite it’s easier to implement and to manage in small environments. It’s configured on Layer 3 interfaces, either physical or SVI interfaces.

Let’s have a look at the topology below and it's routing table:

As we can see, all sites can reach each other. 

Let’s start configuring VRF Lite on ISP. Be aware that when you associate the interface to a VRF it will remove ip assignment.

In configuration mode:

ip vrf SITE_A

exit

ip vrf SITE_B

exit

Then we go to interface configuration mode and assign each interface to its VRF:

Let’s check again our routing table:

Testing reachability from ISP to CE.

Things look different right now, see what happens when we specify the VRF name:

As you can see, VRF Lite is very easy to implement and your customer doesn’t need to change anything on his side.

 

I’ll see on my next post.

Thanks for viewing.

SC


要查看或添加评论,请登录

Silésio Carvalho的更多文章

  • The Power of Visualization

    The Power of Visualization

    I am Silésio Carvalho, CCIE #65745 and I passed the CCIE lab exam on November 30 2021. If you paid attention to the…

    8 条评论
  • ForticlientEMS fails connection with Fortihate

    ForticlientEMS fails connection with Fortihate

    For those trying to play with Fortigate ZTNA, if you're using Fortigate on evaluation mode, one of the restrictions…

  • Why you won't become a CCIE

    Why you won't become a CCIE

    I'm not the author for the text below but I wanted to share this with you, in case you're thinking about taking the…

    10 条评论
  • Trobleshoot SD-WAN – Part 2

    Trobleshoot SD-WAN – Part 2

    Hi there, in the last article we saw how to troubleshoot control connection failure on Cisco SD-WAN, caused by…

  • Trobleshoot SD-WAN – Part 1

    Trobleshoot SD-WAN – Part 1

    Hi there, While deploying Cisco SD-WAN you might face control connection errors related to certificate. Here are some…

  • Como eu come?aria de novo, em Networking (Redes)?

    Como eu come?aria de novo, em Networking (Redes)?

    Estou nesta jornada a mais de uma década e até a data, tem sido uma caminhada nada fácil (por op??o minha) mas muito…

    6 条评论
  • CCIE - The Plan

    CCIE - The Plan

    Hi there, first of all, I’d like thank everyone for the congratulations messages. As a thank you back, I’ll share with…

    20 条评论
  • How To's - Deploy Checkpoint Remote Access VPN

    How To's - Deploy Checkpoint Remote Access VPN

    Hi there, in this post we'll see how to deploy remote access using Checkpoint Remote Access VPN client. Some…

    3 条评论
  • How To’s – Deploy DMVPN Front Door VRF (automating with ansible)

    How To’s – Deploy DMVPN Front Door VRF (automating with ansible)

    Hi there, in this post we're going to deploy DMVPN Front Door VRF and using ansible. Basically, we'll be using DMVPN…

    1 条评论
  • How To’s – Deploy DMVPN Dual Hub Dual Cloud

    How To’s – Deploy DMVPN Dual Hub Dual Cloud

    Hi there, in this post we’ll see how to deploy DMVPN Dual Hub Dual Cloud. Basically it means we’ll have two or more…

社区洞察

其他会员也浏览了